Privacy Policy
How Many UGC collects, uses, and protects account, creator, campaign, and connected Instagram, Facebook, TikTok, and YouTube data.
The Short Version
Many UGC is the platform our team and our creators use to run content campaigns. Creators connect the social accounts they post from, and their posts and performance numbers flow in automatically, so nobody has to screenshot analytics or paste view counts into a spreadsheet.
We collect what we need to run campaigns and nothing else. We don't sell data. We don't run ads. We don't build advertising profiles. When you disconnect a social account, the connection data goes with it.
Who This Policy Covers
Three groups of people touch Many UGC: our internal team, the creators we invite to work on campaigns, and clients who view the report links we share with them. Access is invite-only, with no public signup.
If a client opens one of our shared report links, we don't require them to create an account or log in, and we collect nothing from them beyond standard server logs, unless they choose to enter an email for milestone alerts or content downloads.
What We Collect
Account basics. Your name, email address, profile photo, and, if you choose to provide them during onboarding, phone number, age, gender, country, languages, and shipping address (used when a campaign involves sending you product). We also keep login and session records.
Work you do in the platform. Draft videos you upload, captions, review feedback, chat messages, support tickets, job applications, signed campaign agreements, and activity like approvals and checklist completions.
Connected social accounts. When you connect Instagram, Facebook, TikTok, or YouTube through the provider's login flow, we receive what you approve on their consent screen: your account ID, username, profile photo, access tokens, post metadata, and performance metrics (views, likes, comments, shares, posting times), refreshed on a schedule through the providers' official APIs.
Public handle tracking. A team can also track a public social handle without a login. In that case we collect only what is publicly visible on that profile, meaning public posts and their public counts, through data-collection service providers.
Account logins, when a team stores them. Some campaigns run on brand-owned social accounts. If a login for one of those accounts is stored in the platform, it is encrypted, visible only to specifically authorized people, and every reveal is recorded in an audit log.
Usage and diagnostics. Standard product analytics and error reports so we can see what's breaking and fix it. Cookies are used to keep you signed in.
How We Use It
To run campaigns. Matching your posts to the right campaign, tracking progress against posting targets, and calculating leaderboards and creator stats.
To review content. When a creator uploads a draft video, it is transcribed and analyzed, including with AI tools, so reviewers can give faster, more consistent feedback. The analysis is only used inside the review workflow.
To publish, only when you ask. If a creator turns on auto-publish for a specific approved video, we publish that video to the account they chose. We never post to anyone's account on our own initiative.
To report. Rolling posts and metrics up into campaign reports, weekly summaries, and the share links clients use to see how their campaign is going.
To reach you. Notifications about approvals, feedback, campaign changes, and payouts, by email, in-app, and by SMS or push if you've turned those on. You can switch email and SMS off in Settings.
To keep the platform safe. Authentication, access control, fraud prevention, and debugging.
We never use your data for advertising, sell it to anyone, or share it with data brokers.
Instagram and Facebook (Meta)
When you connect an Instagram or Facebook account, Many UGC requests only the permissions shown on Meta's consent screen: identifying the connected account, reading your posts and their performance metrics, and, if you use auto-publish, publishing approved videos to the account you selected. Metrics refresh roughly hourly through Meta's official APIs.
Our use of data received from Meta's platform follows Meta's Platform Terms and Developer Policies. We do not use Meta data for advertising and we do not pass it to third parties beyond the service providers that host and operate Many UGC.
You can revoke Many UGC's access at any time from your Instagram or Facebook settings under connected apps ("Apps and Websites" / "Business Integrations"). If you remove the app there, Meta sends us an automated deletion callback and we delete your stored tokens and provider identifiers. See the Data Deletion page for details.
TikTok
When you connect TikTok, Many UGC receives what you approve on TikTok's consent screen: your basic profile (account ID, display name, avatar) and your public videos with their performance metrics, through TikTok's official APIs. We use this only to attribute your posts to campaigns and report on their performance.
You can revoke access at any time in the TikTok app under Settings and privacy, then Security & permissions, then Apps and services. Once revoked, syncing stops and we delete the stored access tokens. Our use of TikTok data follows TikTok's Developer Terms of Service.
YouTube and Google
For YouTube, Many UGC requests the youtube.readonly scope to read channel metadata and video performance metrics for YouTube Shorts. We do not upload, modify, or delete any YouTube content. You can revoke access at any time via your Google Account permissions page (https://myaccount.google.com/permissions).
Many UGC's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements. We do not use YouTube data for advertising, do not sell or transfer it to third parties, do not use it to build advertising profiles, and do not use it for surveillance.
Who Sees What
Inside Many UGC, access is role-based. Team members see the campaigns, creators, submissions, and metrics they need to operate. Creators see their own work, their own stats, and the campaigns they're on.
Client report links. When we share a report link with a client, that page shows campaign posts, the handles that posted them, and performance metrics. It never exposes access tokens, contact details, or anything beyond the campaign being reported on. Progress links can additionally show account handover details when a team explicitly chooses to share them, and those reveals are logged.
Slack. If our team connects Slack, campaign updates and reports the team chooses to send are posted into the client's Slack channel.
Service providers. We use vendors for hosting, file storage, email and SMS delivery, authentication, AI content analysis, public-data collection, customer support, product analytics, and error tracking. They process data only to provide those services to Many UGC, and none of them may use your data for their own purposes.
We may disclose information if the law genuinely requires it. We do not sell personal information, and we never share OAuth tokens with advertisers, data brokers, or any unrelated party.
How Long We Keep It
We keep data for as long as it's needed to run the campaigns it belongs to. Posts and metrics already attributed to a campaign remain part of that campaign's record, because clients and creators rely on that history. When a client engagement ends, metric syncing for that brand winds down and stops.
When you disconnect a social account, we delete the stored access tokens and provider identifiers for it. When your relationship with the team ends, you can ask us to delete your account data entirely.
To request deletion, email support@weoper8.com from the address on your account, or see the Data Deletion page. Some records, such as signed agreements, payout history, and security and audit logs, may be retained where we're legally or contractually required to keep them.
Security
Access tokens and stored account logins are encrypted at rest and never exposed in the browser to anyone who isn't authorized to see them. Sensitive actions, such as revealing a stored login or viewing the platform as another user, are restricted by role and written to an audit log.
No online service can promise perfect security. If we find a security issue affecting your information, we'll act on it and tell the people affected based on the nature and scope of the issue.
Your Choices
You can edit your profile and notification preferences in Settings, disconnect social accounts from the provider's side at any time, and email us to access, correct, or delete the information we hold about you.
If you're in a region that gives you specific legal rights over your data (such as the GDPR or CCPA), you can exercise them by emailing support@weoper8.com. We'll respond to every reasonable request; we may ask you to verify your identity first.
Children
Many UGC is not directed to children under 13, and we don't knowingly collect information from them. Connected social accounts must belong to people old enough to hold them under the relevant platform's own terms.
Deletion Timing
Automated Meta callbacks are processed immediately when the signature is valid and the account matches. Manual requests are reviewed by support; we may ask for reasonable verification first, and we aim to complete them within 30 days.
Changes and Contact
If we change this policy in a way that matters, we'll update the effective date above and, for significant changes, tell active users directly.
Questions, access requests, and privacy concerns: support@weoper8.com.
